【24h】

A New Approach to Multimedia Files Carving

机译:多媒体文件雕刻的新方法

获取原文

摘要

Traditional file recovery methods rely on file system information, which are ineffective when file system information isn't available. File carving is a file recovery method that recovers files according to their structure and content without file system information, which is widely used in digital forensics. As the important carriers of digital information, multimedia files are important digital evidence. In this paper, a new multimedia file carving approach is proposed to improve the recovery accuracy of high entropy file fragments. The fragmented files can be recovered by a hierarchical carving process, including file header identification via entropy, file fragment type classification, and file reassembly via parallel unique path approach. A new file type classification method is constructed based on support vector machine, by using the features of BFD (byte frequency distribution) and ROC (rate of change). Four different datasets, such as DFRWS 2006/2007 challenge datasets, dataset simulating actual disk, dataset with randomly disordered fragments, and dataset with biomedical images, are employed in our experiments. The results show that JPEG recovery accuracy is improved greatly compared with that of Photo Rec tool. Our method performs best in the situation where the order of fragments is completely confusing.
机译:传统的文件恢复方法依赖于文件系统信息,当文件系统信息不可用时,这种方法无效。文件雕刻是一种文件恢复方法,可以根据文件的结构和内容恢复文件而无需文件系统信息,这在数字取证中已广泛使用。作为数字信息的重要载体,多媒体文件是重要的数字证据。本文提出了一种新的多媒体文件雕刻方法,以提高高熵文件碎片的恢复精度。碎片文件可以通过分层雕刻过程来恢复,包括通过熵识别文件头,文件碎片类型分类以及通过并行唯一路径方法进行文件重组。利用BFD(字节频率分布)和ROC(变化率)的特征,在支持向量机的基础上构造了一种新的文件类型分类方法。在我们的实验中,使用了四个不同的数据集,例如DFRWS 2006/2007挑战数据集,模拟实际磁盘的数据集,具有随机无序碎片的数据集以及具有生物医学图像的数据集。结果表明,与Photo Rec工具相比,JPEG恢复精度大大提高。在片段顺序完全混乱的情况下,我们的方法效果最好。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号